nerdexam
PECB

ISO-IEC-27001-LEAD-AUDITOR · Question #73

Objectives, criteria, and scope are critical features of a third-party ISMS audit. Which two issues are audit objectives?

The correct answer is B. Assess conformity with ISO/IEC 27001 requirements D. Confirm sites operating the ISMS. Audit objectives are the specific purposes or goals that the customer or the certification body wants to achieve through the audit. They define what the audit intends to accomplish and provide the basis for planning and conducting the audit. Audit objectives may vary depending…

Audit Objectives and Scope

Question

Objectives, criteria, and scope are critical features of a third-party ISMS audit. Which two issues are audit objectives?

Options

  • AEvaluate customer processes and functions
  • BAssess conformity with ISO/IEC 27001 requirements
  • CFulfil the audit plan
  • DConfirm sites operating the ISMS
  • EDetermine the scope of the ISMS
  • FReview organisation efficiency

How the community answered

(37 responses)
  • A
    3% (1)
  • B
    89% (33)
  • E
    3% (1)
  • F
    5% (2)

Explanation

Audit objectives are the specific purposes or goals that the customer or the certification body wants to achieve through the audit. They define what the audit intends to accomplish and provide the basis for planning and conducting the audit. Audit objectives may vary depending on the type, scope, and criteria of the audit, but they should be clear, measurable, and achievable. Some examples of audit objectives for a third-party ISMS audit are: Assess conformity with ISO/IEC 27001 requirements: This objective means that the audit aims to verify that the organisation's ISMS meets the requirements of the ISO/IEC 27001 standard, which specifies the best practices for establishing, implementing, maintaining, and improving an information security management system. The audit will evaluate the organisation's ISMS documentation, processes, controls, and performance against the standard's clauses and annex Confirm sites operating the ISMS: This objective means that the audit aims to confirm that the organisation's ISMS covers all the relevant sites or locations where the organisation operates or provides its services. The audit will verify that the scope of the ISMS is accurate and consistent with the organisation's context, objectives, and risks.

Topics

#audit objectives#third-party audit#ISO 27001 conformity#audit scope

Community Discussion

No community discussion yet for this question.

Full ISO-IEC-27001-LEAD-AUDITOR Practice